<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to optimize the ingestion of data from Splunk Universal Forwarder to Splunk Indexer in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-optimize-the-ingestion-of-data-from-Splunk-Universal/m-p/680686#M113722</link>
    <description>&lt;P&gt;thanks&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp; with that change,&amp;nbsp; around 5 million logs were ingested in couple of mins.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 14 Mar 2024 13:04:24 GMT</pubDate>
    <dc:creator>sdhiren</dc:creator>
    <dc:date>2024-03-14T13:04:24Z</dc:date>
    <item>
      <title>How to optimize the ingestion of data from Splunk Universal Forwarder to Splunk Indexer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-optimize-the-ingestion-of-data-from-Splunk-Universal/m-p/680677#M113718</link>
      <description>&lt;P&gt;I have a splunk universal forwarder, which is indexing a 1 GB log file to a Splunk Indexer. The problem I am facing is the ingestion is happening very slow (100K log entries per mins). I have tried setting the&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;parallelIngestionPipelines = 2&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;setting for both Indexer and Forwarder, but to no avail.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Below are the stats for the containers running Indexer and forwarder&lt;/P&gt;&lt;P&gt;CONTAINER_ID NAME CPU % MEM USAGE / LIMIT MEM % NET I/O BLOCK I/O PIDS&lt;BR /&gt;ecb272b9ca6b tracing-splunk-1 12.15% 260.8MiB / 7.674GiB 3.32% 366MB / 1.85MB 0B / 1.01GB 239&lt;/P&gt;&lt;P&gt;CONTAINER_ID NAME CPU % MEM USAGE / LIMIT MEM % NET I/O BLOCK I/O PIDS&lt;BR /&gt;0ac17f935889 tracing-splunkforwarder-1 0.70% 68.22MiB / 7.674GiB 0.87% 986kB / 312MB 0B / 18.2MB 65&lt;/P&gt;&lt;P&gt;We are running these in a docker container&lt;/P&gt;&lt;P&gt;I and my team is pretty new to Splunk eco system. Can someone please help us to optimize the ingestion of logs.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2024 11:16:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-optimize-the-ingestion-of-data-from-Splunk-Universal/m-p/680677#M113718</guid>
      <dc:creator>sdhiren</dc:creator>
      <dc:date>2024-03-14T11:16:07Z</dc:date>
    </item>
    <item>
      <title>Re: How to optimize the ingestion of data from Splunk Universal Forwarder to Splunk Indexer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-optimize-the-ingestion-of-data-from-Splunk-Universal/m-p/680682#M113721</link>
      <description>&lt;P&gt;Make sure you have this in limits.conf on the UF&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[thruput]
maxKBps = 0&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2024 12:23:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-optimize-the-ingestion-of-data-from-Splunk-Universal/m-p/680682#M113721</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2024-03-14T12:23:18Z</dc:date>
    </item>
    <item>
      <title>Re: How to optimize the ingestion of data from Splunk Universal Forwarder to Splunk Indexer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-optimize-the-ingestion-of-data-from-Splunk-Universal/m-p/680686#M113722</link>
      <description>&lt;P&gt;thanks&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp; with that change,&amp;nbsp; around 5 million logs were ingested in couple of mins.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2024 13:04:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-optimize-the-ingestion-of-data-from-Splunk-Universal/m-p/680686#M113722</guid>
      <dc:creator>sdhiren</dc:creator>
      <dc:date>2024-03-14T13:04:24Z</dc:date>
    </item>
  </channel>
</rss>

